2.3 Network protection
Network security encompasses the structures, transmission methods, transport formats, and security measures used to provide confidentiality, integrity, and availability for transmissions over private and public communications networks and media. Renewi’s network is the most central asset in its total ICT infrastructure. Loss of network assurance on any level can have devastating consequences. A well-architected and well-protected network is a key element for the protection against Renewi’s threats.
Key principles:
Network segmentation / Quarantined zones
The Renewi network is segmented based on the vulnerability level of the information stored on the servers. Unsupported systems or SCADA/PLC systems are isolated from the office network. Separate VLANS are set up with firewall filtering to ensure that only authorized individuals are only able to communicate with systems necessary to fulfil their specific responsibilities.
Limitation and control of network ports, protocols, and services
Attackers search for remotely accessible network services that are vulnerable to exploitation. Common examples include poorly configured web servers, mail servers, file and print services, and domain name system (DNS) servers installed by default on a variety of different device types, often without a business need for the given service. Renewi therefore has only ports, protocols, and services with validated business running on each system.
Secure communications
Communication between network components within the internal private Renewi network or the public internet occurs through the standard protocols from the TCP/IP-model (e.g. HTTP, FTP, etc.). When confidential information is disclosed over the public internet, secure protocols are used (e.g. SSL/TLS).
Remote access
All remote administration of and access to Renewi servers, workstations, network devices, and similar equipment are over secure channels. Protocols such as telnet, VNC, RDP, or others that do not actively support strong encryption are only used if they are performed over a secondary encryption channel, such as SSL, TLS or IPSEC.
Wireless access
Only authorized and corporately managed wireless access points are allowed to connect to the Renewi network. Wireless devices connected to the Renewi network must have a configuration and security profile. All wireless traffic have at least Advanced Encryption Standard (AES) encryption used with at least Wi-Fi Protected Access 2 (WPA2) protection. Access to for those wireless devices to the network that do not have such a configuration and profile is denied. For such untrusted devices a separate wireless network (‘guest’ network) is configurated that is segregated from the internal Renewi network.